Governance Policy

I. Role Definitions

a. Staff

  • Responsible for handling inquiries, contacting customers, generating quotations, and updating the status of inquiries.
  • Can view, edit, and manage inquiries and quotations within their scope of work.
  • Accountable for any misuse or unauthorized activities performed under their account.

b. Admin

  • Oversees the entire system, including staff management, activity monitoring, and system maintenance.
  • Has the authority to add, edit, and delete staff accounts.
  • Ensures all security and governance policies are enforced.

II. Access Control

a. Access Registration

  • New access requests or registration of new staff must be referred to or consulted with the admin.
  • Admins are responsible for creating, modifying, and deleting user accounts.

b. Authentication and Authorization

  • The system must authenticate all users (staff and admin) to ensure secure access.
  • Role-based access control is implemented to provide different levels of access for staff and admins.

III. Security Measures

a. Account Misuse Accountability

Any misuse or unauthorized activities on staff accounts will be the responsibility of the respective staff member.

b. Password Reset Protocol

If a staff member forgets their password, they must contact the admin for a password reset.

c. Activity Logging

  • All activities performed by staff while using the system will be recorded in the access log.
  • Admins can review these logs to monitor staff activities and ensure compliance with policies.

d. Data Protection

  • All sensitive data must be encrypted during transit and at rest.
  • Regular data backups must be conducted, and a disaster recovery plan must be in place.

IV. Operational Guidelines

a. Staff Guidelines

  • Staff must follow the defined procedures for handling inquiries, generating quotations, and updating inquiry statuses.
  • Staff must contact customers to confirm inquiry details and ensure accurate information is recorded.
  • Any changes to inquiry details must be updated promptly in the system.

b. Admin Guidelines

  • Admins must manage user accounts, ensuring that only authorized personnel have access to the system.
  • Admins are responsible for monitoring system activity, reviewing access logs, and addressing any security incidents.
  • Admins must ensure that the system is regularly updated and maintained to prevent security vulnerabilities.

V. Communication and Documentation

a. Communication

  • Clear and consistent communication must be maintained between staff and customers to ensure accurate inquiry handling and quotation generation.
  • Email notifications will be sent to users regarding inquiry receipts and quotations.

b. Documentation

Comprehensive documentation must be maintained for all system functionalities, APIs, and configurations.

Staff and admins must be trained on using the system and understanding the governance policies.

VI. Compliance and Review

a. Policy Compliance

  • All staff and admins must adhere to the governance policy and ensure their actions align with the defined procedures and security measures.

b. Policy Review

  • The governance policy will be reviewed periodically to ensure its effectiveness and relevance.
  • Any changes to the policy will be communicated to all staff and admins.